Zum Inhalt springen

Cloudflare Release Notes

1.616 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

AI Search indexiert R2-Objekte ohne Dateiendung

AI Search kann R2-Objekte ohne Dateiendung indexieren, sofern sie unterstützte Content-Type-Metadaten besitzen, wobei die Dateityp-Validierung erhalten bleibt.

AI Search

AI Search can index R2 objects without filename extensions when they include supported Content-Type metadata. This supports object keys that do not include file extensions while preserving file-type validation during indexing.

For supported file types and Content-Type requirements, refer to R2 data sources.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Neue Workflows auf Workers Paid: Standard-Aufbewahrung von sieben Tagen

Neue Workflows auf Workers Paid, die ab dem 10. September 2026 erstellt werden, behalten Instanzzustände standardmäßig sieben statt 30 Tage, während bestehende Workflows unverändert bleiben.

Workflows created on or after September 10, 2026, on the Workers Paid plan retain completed and errored instance state for seven days by default (previously 30 days). The seven day default helps to reduce storage costs by default. The maximum retention limit remains 30 days.

The retention period for existing Workflows is unchanged. The Workers Free plan retains its three-day default and limit.

To set the retention period for a Workflow instance, specify successRetention, errorRetention, or both:

const instance = await env.MY_WORKFLOW.create({
	retention: {
		successRetention: "2 days",
		errorRetention: "30 days",
	},
});
const instance = await env.MY_WORKFLOW.create({
	retention: {
		successRetention: "2 days",
		errorRetention: "30 days",
	},
});

You can also set the retention period per Workflow and per instance in the Cloudflare dashboard ↗︎.

For retention details, refer to Workflows pricing and the WorkflowInstanceCreateOptions API reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Cloudflare Containers mit Codex über die OpenAI Agents API nutzen

The OpenAI Agents API gives your application access to Codex through an OpenAI-managed API.

OpenAI manages sessions, orchestration, context compaction, and recovery while your application provides tools and uses Cloudflare Containers as the execution environment.

Cloudflare Containers can now provide self-hosted execution environments for the OpenAI Agents API. The open-source OpenAI Agents API Workers template ↗︎ provides a reference implementation. The Worker maintains a Cloudflare Container for each Codex session, keeps active work running, reconnects on follow-up input, and shuts down automatically when idle.

You can configure the reference implementation to meet your needs by extending the Container to provide controlled access to data and the network or by integrating it with other Cloudflare products.

To get started, refer to Run Codex on Cloudflare using the OpenAI Agents API.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Emergency Release 2026-09-10: Adobe Commerce/Magento RCE

Eine neue Block-Regel schützt vor der aktiv ausgenutzten RCE-Schwachstelle CVE-2026-75650 in Adobe Commerce und Magento Open Source, ersetzt aber nicht das Einspielen des Hotfixes aus APSB26-146.

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.

Key Findings

  • Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.

Impact

This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...440f5c55

N/A

Adobe Commerce - Remote Code Execution - CVE:CVE-2026-75650

N/A

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

AI Gateway von Cloudflare

AI Gateway: Benutzerdefinierte Kosten unterstützen Cache-Tokens

Benutzerdefinierte Kosten in AI Gateway unterstützen über den Header cf-aig-custom-cost nun separate Preise für Cache-Read- und Cache-Write-Tokens.

AI Gateway custom costs now support cache-read and cache-write token rates. This lets custom cost metrics reflect negotiated cache pricing across providers.

Add per_cache_read_token or per_cache_write_token to the cf-aig-custom-cost header:

{
	"per_token_in": 0.000001,
	"per_token_out": 0.000002,
	"per_cache_read_token": 0.0000001,
	"per_cache_write_token": 0.0000005
}

Cache-token pricing activates when either cache rate is present. An omitted cache rate defaults to per_token_in. If both cache rates are omitted, AI Gateway preserves the existing input and output calculation.

Providers can include cache tokens within input tokens or report them separately. AI Gateway automatically accounts for these differences and prevents double-counting.

For more information, refer to Custom costs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.8.1290.1 (Beta)

Das Beta-Release 2026.8.1290.1 des Cloudflare One Client für macOS unterstützt das Routing nicht-RFC-1918-konformer lokaler IPv4-Netze durch den WARP-Tunnel und verbessert die DNS- und API-Zuverlässigkeit, außerdem behebt es mehrere Fehler.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • Fixed Extra Logging failing to capture packets across all interfaces.
  • Fixed an issue that could prevent remote diagnostics from completing.
  • Fixed DNS connectivity checks failing on IPv6-only networks.
  • Fixed the client service exiting when its route-monitoring socket was closed after sleep or wake.
  • Fixed DNS enforcement checks making the client service unresponsive on systems with large routing tables.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
  • Fixed the client continuing to report 'No network' after a successful manual disconnect. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.8.1290.1 (Beta)

Das Beta-Release 2026.8.1290.1 des Cloudflare One Client für Windows unterstützt das Routing nicht-RFC-1918-konformer lokaler IPv4-Netze, benötigt den Windows-Dienst WLAN AutoConfig nicht mehr und behebt mehrere Fehler, etwa bei DEX-HTTP-Tests und beim Start der Client-Oberfläche.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This beta release includes the following changes and improvements:

  • Added support for routing non-RFC 1918 local IPv4 networks through the WARP tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
  • Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
  • Improved API reliability by retrying requests dropped when reusing pooled connections.
  • The client no longer requires the Windows WLAN AutoConfig service to be running.
  • Implemented a service recovery mechanism backed by Windows scheduler task to start WARP service on system unlock if not already started.
  • Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
  • Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
  • Fixed the client continuing to report 'No network' after a successful manual disconnect.
  • Fixed Digital Experience Monitoring (DEX) HTTP tests failing TLS validation on Windows.
  • Fixed the client UI crashing at startup when it could not write to the Windows registry. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browser Isolation: Verbesserte Tap-to-type-Eingabe unter iOS

Browser Isolation zeigt die Tap-to-type-Aufforderung auf iOS-Geräten jetzt inline über dem fokussierten Textfeld statt als Vollbild-Overlay, bei sehr kleinen Feldern erscheint stattdessen ein Tastatursymbol.

Browser Isolation has improved the tap-to-type experience for users on iOS devices.

Previously, Browser Isolation displayed a full-screen overlay with the message tap to type when users focused a text field. The prompt now appears inline over the focused text field, reducing disruption when users enter text in isolated sessions.

If the focused text field is too small to display the full prompt, Browser Isolation displays a keyboard icon in the center of the text field instead.

Inline tap-to-type prompt over a focused text field in Browser Isolation

iOS users should tap twice to begin entering text. This update applies automatically to Browser Isolation sessions on iOS.

For more information on why this interaction is required, refer to iOS limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Neue Integration für Zoom

Cloudflare CASB lässt sich jetzt per vorgefertigter OAuth-Anwendung mit Zoom integrieren und scannt Kontoeinstellungen, Benutzerkonten und Meetings fortlaufend auf Sicherheitsbefunde.

Cloudflare CASB now integrates with Zoom. The integration connects through Cloudflare's pre-built OAuth application — no manual app setup in Zoom is required. After an initial scan, CASB continuously scans your Zoom account to surface new findings as your environment changes.

Zoom is widely used for meetings, webinars, and collaboration. Misconfigurations in account settings, meeting security controls, and recording access can expose organizations to data leakage, unauthorized access, and compliance risk. Cloudflare CASB ingests Zoom account data via API to surface security findings across these areas.

Key capabilities

Starting today, security teams can scan for security findings across the following assets:

  • Account settings — Detect weak password policies, unlocked security controls, and two-factor authentication gaps across your Zoom account
  • User accounts — Identify users not enforcing SSO, accounts with insecure host keys, unverified or inactive users, and unsafe overrides of account-level security settings
  • Meetings — Surface meetings without passwords or waiting rooms, meetings using Personal Meeting IDs (PMIs), and meetings with external domain hosts …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Gateway: Benutzerdefinierte Kosten unterstützen Cache-Tokens

Benutzerdefinierte Kosten in AI Gateway unterstützen jetzt Raten für Cache-Read- und Cache-Write-Tokens über den Header cf-aig-custom-cost.

AI Gateway custom costs now support cache-read and cache-write token rates. This lets custom cost metrics reflect negotiated cache pricing across providers.

Add per_cache_read_token or per_cache_write_token to the cf-aig-custom-cost header:

{
	"per_token_in": 0.000001,
	"per_token_out": 0.000002,
	"per_cache_read_token": 0.0000001,
	"per_cache_write_token": 0.0000005
}

Cache-token pricing activates when either cache rate is present. An omitted cache rate defaults to per_token_in. If both cache rates are omitted, AI Gateway preserves the existing input and output calculation.

Providers can include cache tokens within input tokens or report them separately. AI Gateway automatically accounts for these differences and prevents double-counting.

For more information, refer to Custom costs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

AI Gateway Custom Costs unterstützen Cache-Tokens

AI Gateway Custom Costs unterstützen jetzt Raten für Cache-Read- und Cache-Write-Tokens über per_cache_read_token und per_cache_write_token im Header cf-aig-custom-cost.

AI Gateway

AI Gateway custom costs now support cache-read and cache-write token rates. This lets custom cost metrics reflect negotiated cache pricing across providers.

Add per_cache_read_token or per_cache_write_token to the cf-aig-custom-cost header:

{
	"per_token_in": 0.000001,
	"per_token_out": 0.000002,
	"per_cache_read_token": 0.0000001,
	"per_cache_write_token": 0.0000005
}

Cache-token pricing activates when either cache rate is present. An omitted cache rate defaults to per_token_in. If both cache rates are omitted, AI Gateway preserves the existing input and output calculation.

Providers can include cache tokens within input tokens or report them separately. AI Gateway automatically accounts for these differences and prevents double-counting.

For more information, refer to Custom costs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Observability pro Container-Anwendung konfigurieren

Observability lässt sich beim Deployment mit Wrangler jetzt pro Container-Anwendung konfigurieren und optional auf einen Teil der laufenden Instanzen anwenden.

You can now configure observability for each container application when you deploy Containers with Wrangler. This lets you change logging for one container without changing the rest of your Worker.

If you omit containers[].observability, Wrangler uses the top-level observability setting for that container. If you set it, the container setting overrides the top-level setting.

Use target_instance_percentage or target_instance_count to apply an observability change to a subset of running instances.

{
	"observability": {
		"enabled": false,
	},
	"containers": [
		{
			"class_name": "MyContainer",
			"image": "./Dockerfile",
			"observability": {
				"enabled": true,
				"target_instance_percentage": 25,
			},
		},
	],
}
[observability]
enabled = false

[[containers]]
class_name = "MyContainer"
image = "./Dockerfile"

  [containers.observability]
  enabled = true
  target_instance_percentage = 25

For more information about Workers Logs, refer to Workers Logs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Miniflare v5 bereitet lokale Entwicklung für die cf CLI vor

Miniflare v5 führt eine neue Konfigurationsstruktur ein und entfernt veraltete APIs als Vorbereitung auf die kommende cf CLI, erfordert für die meisten Projekte aber keine Aktion.

Miniflare v5 prepares Cloudflare local development tooling for the upcoming cf CLI.

Miniflare powers local Workers development behind wrangler dev, the Cloudflare Vite plugin, and @cloudflare/vitest-plugin. Most projects should use those tools instead of depending on Miniflare directly, and Miniflare v5 will not require any action.

The most significant change is a new configuration shape which aligns Miniflare with cloudflare.config.ts, the programmatic Cloudflare configuration format now available for testing.

Other breaking changes include:

  • Removed deprecated APIs and options, such as legacy alpha D1 bindings.
  • Removed now-unused, internal APIs like wrappedBindings
  • Removed Miniflare's built-in module discovery; higher-level tools like Wrangler and the Vite plugin should be providing the module graph.
  • Moved local-only /cdn-cgi routes under /cdn-cgi/local.
  • Replaced per-resource persistence options with shared persistence root options.

For a more comprehensive list, refer to Miniflare's changelog ↗︎

This work sets up a cleaner foundation for the next generation of local development tooling, including the new cf CLI.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Python 3.14 für Python Workers

Neue Python Workers mit Compatibility Date 2026-09-08 oder später nutzen standardmäßig Python 3.14 mit Pyodide 314.0.6.

Python workers now use Python 3.14 by default.

This change applies to all new Python workers using compatibility date 2026-09-08 or later.

Internally, this change updates the Pyodide runtime to 314.0.6.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Radar-Suche umfasst jetzt Internet-Ereignisse

Die Cloudflare-Radar-Suche liefert jetzt auch Internet-Ereignisse und Ausfälle, wobei Links den Datumsbereich des Ereignisses beibehalten und die Ergebnisse auch für browserbasierte KI-Agenten über WebMCP verfügbar sind.

Radar

Cloudflare Radar search now includes Internet events and outages alongside existing results. Search event descriptions or related entities, such as locations, ASes, bots, and top-level domains, to find relevant events and open the most relevant Radar view.

Radar search results showing Internet outage events associated with locations and autonomous systems

Event links preserve the event date range, making it easier to investigate what changed before, during, and after an event. These results are also available to browser-based AI agents through WebMCP.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-08: Next.js-RCE-Beta-Regeln zusammengeführt

Die Beta-Regeln zu Next.js Image Optimizer RCE via AVIF und CVE-2026-75604 werden in die jeweiligen Originalregeln überführt und von Log auf Block gesetzt.

This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...c76ba662

N/A

Next.js - Image Optimizer Remote Code Execution via Crafted AVIF - Beta

Log

Block

This rule is merged into the original rule "Next.js - Image Optimizer Remote Code Execution via Crafted AVIF" (ID: ...80256efe).

Cloudflare Managed Ruleset

...208457cf

N/A

Next.js - Remote Code Execution - CVE:CVE-2026-75604 - Beta

Log

Block

This rule is merged into the original rule "Next.js - Remote Code Execution - CVE:CVE-2026-75604" (ID: ...2ca6cce3).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Radar-Suche enthält jetzt Internet-Ereignisse

Die Cloudflare-Radar-Suche liefert jetzt zusätzlich Internet-Ereignisse und Ausfälle, wobei Ereignislinks den Datumsbereich beibehalten und die Ergebnisse auch für browserbasierte KI-Agenten über WebMCP verfügbar sind.

Radar

Cloudflare Radar search now includes Internet events and outages alongside existing results. Search event descriptions or related entities, such as locations, ASes, bots, and top-level domains, to find relevant events and open the most relevant Radar view.

Radar search results showing Internet outage events associated with locations and autonomous systems

Event links preserve the event date range, making it easier to investigate what changed before, during, and after an event. These results are also available to browser-based AI agents through WebMCP.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Application Profiles für Positive Security

Application Profiles ergänzen die WAF um eine Positive-Security-Ebene, bei der Schema Profiles gültige Anfragen lernen und abweichenden Traffic ohne Blockierung klassifizieren, wobei die Durchsetzung per Custom Rule erfolgt und für Enterprise-Kunden ohne API Security eine geschlossene Beta startet.

Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that deviates from the expected structure.

The first available profile type, Schema Profiles, can learn path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies. Profiles model field types and constraints such as numeric ranges, string lengths, and character classes. After a profile becomes available, an always-on detection classifies requests as conforming or non-conforming without blocking traffic.

Use Profile Analysis in Security Analytics to review conformance trends and sampled violation details before enforcing a profile. When you are ready to mitigate traffic, use a Custom Rule to scope enforcement by hostname, path, operation, or other security signals such as Attack Score.

Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is also opening a closed beta to invited Enterprise customers without API Security. Contact your Cloudflare account team to express interest.

For more information, refer to Application Profiles.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF: Attack Signature Detection im Early Access

Attack Signature Detection ist im Early Access verfügbar, gleicht Anfragen mit Cloudflare-Angriffssignaturen ab und protokolliert Treffer in Security Analytics > Attack Analysis, ohne Maßnahmen anzuwenden.

Attack Signature Detection is now available in Early Access. It evaluates requests against Cloudflare attack signatures and records matches without applying a mitigation action, allowing you to investigate detected traffic before deciding how to respond.

In Security Analytics > Attack Analysis, you can review matching signature references, categories, confidence levels, and request outcomes. You can then use these fields in Security Rules and combine them with request properties such as hostname, path, and HTTP method to apply scoped mitigation.

Attack Signature Detection uses the same signature definitions as Cloudflare Managed Rules, but it does not inherit your Managed Rules actions, overrides, or deployment configuration. Managed Rules remain the recommended baseline protection during Early Access.

Contact your Cloudflare account team to request access. For more information, refer to Attack Signature Detection.

Originalquelle(öffnet in neuem Tab)Problem melden